How to Prepare for Microsoft Certifications Earning a Microsoft Certification could be the beginning or continuation of an enduring career that will include the strengthening of their technical skills, collaboration with other professionals ...

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

50% discount on Microsoft Certifications to ... Hello guys, Prometric is providing for students a 50% discount on Microsoft certifications. The promotion is valid until June 30, 2010. For more details visit the ...

Readmore

Book - Administration and Maintenance Environment ... Hello people, For those who are preparing for the exam 70-290 book Administration and Maintenance Environment Microsoft Windows Server 2003 is a great material. I recommend.

Readmore

Prometric offers vouchers of up to 25% off ... Hello people, I just received an email from Prometric informing a discount of up to 25% on Microsoft Certifications. The promotion is valid until December 31, 2009 or even last for the ...

Readmore

twitter

Twitter Facebook

Microsoft warns of critical flaw affecting applications in ASP.Net

Category: Security

Hackers who discovered the vulnerability estimate that 25% of all sites are subject to attacks due to the problem.

Microsoft warned on Friday (20/09) that a critical flaw in ASP.Net - programming environment on Windows Servers - could be used by hackers to break into encrypted web pages and steal data such as user names and passwords.

The vulnerability was made public that same day, shortly before the announcement of the company, when two researchers who discovered the problem, show how to exploit it at a security conference held in Buenos Aires, Argentina.

According to the statement of the Redmond company, the flaw affects all versions of ASP.Net. Therefore, a correction must be provided for all operating systems still supported, the Windows XP Service Pack 3 (SP3) and Server 2003 to Windows 7 and Server 2008 R2. Other products such as IIS and SharePoint will also be updated.

The hackers responsible for the establishment, Rizzo and Duong, said the attacks that exploit the flaw can access Web applications with administrative priority, resulting from "loss of sensitive data to the complete destruction of the system." They estimate that 25% of all sites use the ASP.Net.

While the correction is not
Although Microsoft has said that a fix is ​​on the way, she did not disclose a timeline. Meanwhile, developers suggests a stopgap measure:

"You can prevent this problem by enabling the use of customError ASP.Net, and set it to always return the same error page - regardless of fault found on the server," wrote Scott Guthrie, some teams responsible for business development, including that runs the ASP.Net. "By directing all error pages to one place, you prevent a hacker to distinguish between the different errors that occurred."

The director of security operations at nCircle Security company confirmed that the vulnerability is "troubling."

"As for public services, people will be afraid to attacks that can access any document. For example, file 'web.config', which are contained in the traditional username / password ".

To help developers, Microsoft has published a script in Visual Basic can detect vulnerability in ASP.Net applications, and provide a unique forum for questions related to the problem.

Hackers use Javascript code to attack users of Twitter

Category: Security , Twitter

Issues such as the World Cup and conflict in the Gaza Strip baits are to install spyware and trojans on your computer of the internet.

Trend Micro has identified a potentially dangerous threat that uses Javascript code to affect users of Twitter . It is the first time that such a strategy is used specifically against members of the microblog.

According to digital security company, the attack is basically an adaptation of the present in phishing messages, an alternative very popular with cybercriminals in recent years. According to Rik Ferguson of Trend research team, both PDF documents and executable files are being used as bait to trick internet users.

"The spy program, to be installed on the machine, tries to download other malware. We are investigating, "he said.

To entice users to click on the link infected, hackers take advantage of the issues that are highlighted on the world stage. In June, for example, the problems in Gaza and the World Cup were elected.

The caution that social network users should have no different posture recommended for other environments of the Internet: "It is best to not click on links sent by unknown people, you never know what the destination address. This is not the first threat on Twitter and certainly not the last, "Ferguson concluded.

Apple fixes 92 bugs, but "forgets" new flaw exploited by hackers

Category: Security

Apple has corrected this Monday (29/3) a record number of failures (almost 40% of them rated critical) in their operating systems Leopard and Snow Leopard: 92. The fixes are part of Security Update 2010-002 .

For the reader an idea, the largest package of fixes released last year fought "only" 67 Vulnerability s. "The number of corrections is so big and scary that you do not even want to see," said the director of nCircle Network Security, Andrew Storms.

The package ends with 42 security bugs in applications or components of Mac OS X's firewall going to the X11, the Mac version of X Windows System. Over 40% of the vulnerabilities addressed are considered critical for allowing the execution of codes used in the invasion and control remote computer s.

The update also brings Snow Leopard to version 10.6.3 (update that fixes bugs related to QuickTime and the AirPort feature, among others), making this the third major update to this version of Apple's operating system, launched in August , 2009.

Despite all these corrections, Charlie Miller , the researcher who last week broke into a system with Snow Leopard during the Pwn2Own hacking competition, which earned him a prize of $ 10,000, says the loophole that he used to control equipment not been corrected.

Hackers hack tool and update care specialists

Category: Internet Explorer , Security

Code released by Metasploit project is more reliable and can be used for attacks that exploit the Internet Explorer flaw.

Hackers working on the project open source Metasploit updated a software created to blitzkrieg the Internet Explorer, making it more reliable, although more likely to be used by criminals.

Security experts have been concerned with the failure since it was released the list of emails Bugtraq, on Friday (20/11). But the original code as an example in the list was not reliable, and has not been used in attacks in the real world.

"The Metasploit version that was released last night will be more reliable for certain attacks that the previous software," said Ben Greenbaum, senior research manager at Symantec, in an interview on Wednesday (25/11).

On Wednesday morning, Symantec had not detected the use of the tool on the Internet attacks, but experts say this type of code is for a very popular hacking technique called drive-by attack.

Code infiltration
Internet users become victims when they visit web sites that contain malicious code. It is then when their machines are infected by the vulnerability of the browser.

Criminals also infiltrate this type of code hacked websites, with the intention of spreading their attacks.

On Monday (23/11), Microsoft published a security advisory on the flaw, offering some workarounds for the problem. It affects versions 6 and 7 of IE.

The browser IE8 is not affected by the bug, which has to do with the way that IE retrieves certain objects Cascading Style Sheet (CSS) used to create a standardized layout on web pages.

IE users can update their more cautious navagedores or disable JavaScript, if you want to prevent attacks.

Security expert dismisses blackout caused by hackers

Category: Security

Security expert Robert Graham ruled that the blackouts of 2005 and 2007 were caused by hackers, but warned that attackers could, yeah, cause blackouts - and without much difficulty, because the energy companies themselves do not know of the problems in your network computer s. These alleged attacks were disclosed by the network of U.S. television CBS on "60 Minutes" earlier this month.
The ONS confirmed on Monday afternoon (16) which suffered its corporate network hacked late on Thursday. However, it ruled that the blackout that hit 18 states on Tuesday (10) was caused by computer hacking. The ONS quotes the Ministry of Mines and Energy, which reconfirmed that the blackout was caused by short circuit .

Robert Graham heard by the G1, is founder and CEO of security firm Errata Security. Specialist in security analysis, it performs penetration testing (pen-tests), a kind of "hacking" authorized by the companies to verify the security of the network itself. Graham has extensive experience in the electricity sector and, in 2006, lectured on the subject in the Black Hat security conference, one of the most important in the world, as part of the research team X-Force at Internet Security Systems (ISS), now part of giant IBM.
Contestation

In response to what was said by "60 Minutes," Graham wrote in his blog : "as a pen-tester, I know that [the grid North American] is insecure. I safety assessment of energy companies. I know I can hack the Internet and cause blackouts. "

Despite the vulnerability , Robert Graham does not believe that blackouts were caused by hackers. To substantiate the allegation that Brazil would have been attacked, "60 minutes" referenced intelligence officers and the army in the United States. These sources, anonymous, fails to convince the expert.

"I have had many experiences with U.S. intelligence agencies. They tend to distort any rumor related to hackers, have an extreme paranoia and will easily be considered as 'fact' things for which there is little or no evidence, "says Graham. "In other areas they do a good job of distinguishing fact and fiction, but it seems like everything that involves hacking scares them."

The specialist does not believe that the lack of electrical networks is a big problem. "There is a risk. Hackers will eventually cause a major blackout. In the grand scheme of things, however, is not so important. Blackouts caused by accidental errors will always be a bigger threat. Member nations exploding transmission lines, pump, always will be a greater threat. Regulatory poor will always be a bigger threat, "he wrote in his blog.

Graham believes that the story of the "60 minutes" is just "propaganda" to sell the idea that the electrical system requires more government intervention to increase their security - which, he said, will not solve the problem.

Vulnerability

0,,32965034 FMMP,00 Especialista em segurança descarta apagão causado por hackers

Photo: Reproduction

Example of the graphical interface of a SCADA system. (Photo: Reproduction)

In an interview with G1, the specialist said he did not believe that attacks on the electrical system happen. And says he has no idea why it does not happen. "I do many tests, and sometimes I'm very surprised that my client has not been hacked," he says. Like other basic services such as water and gas, electricity abastamento is monitored and controlled by systems known as SCADA (Supervisory Control and Data Acquisition or "Systems Monitoring and Data Acquisition").
For businesses, the SCADA is always isolated from the Internet or other networks, which would prevent external attacks. In the experience of the specialist, this is not the case.

Although the experience of Graham is in the United States, there is no reason to believe that the situation is very different in Brazil - including some of the control systems used there are also used here. The speech made ​​by an expert on Black Hat account of several cases where the client - in this case, an energy company - said he was safe because the SCADA network was isolated. Graham proved the contrary, often a simple accessing open wireless network, and finding systems that made the bridge between the networks.


In one case, the computer that connected to the network control system can be compromised with a gap of ten years ago. The computer was never updated.

This is because the characteristics of a SCADA system is that by being part of critical infrastructure, they are rarely updated. "So you can see all kinds of equipment computer stranger, who was installed 20 years ago and never moved, "says the expert. He said the systems that control computers running Windows 95 are "common".

Sometimes specific equipment are used for the task. They are even more insecure than traditional computers, but the fact that they are difficult custom attacks. Unfortunately, the hacker can get information on the company's own network.

"In theory, the hacker would need inside knowledge. In practice, the manuals are on the internet and you can buy cheap discarded equipment on eBay. In our experience, the information is needed on the computers in the corporate network. Then, once we got there, we have all the information to hack into the control network, "says the expert.

The belief that these are isolated systems also leads them to use a weak or null authentication. The challenge is due to arrive in the control network, since the system itself is not secure.

Another misconception, Graham warns, is that criminals can not obtain information about SCADA. In fact, suppliers of such technology provide various data about them in the Internet. In addition, marketing materials with "success stories" reveal what system is used by some suppliers of energy. This public document of the General Electric, for example, reveals that the state Hydroelectric Company of São Francisco (CHESF) makes use of a monitoring product called Universal Relay .

pixel Especialista em segurança descarta apagão causado por hackers